payment-method-development

Warn

Audited by Snyk on Feb 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly about implementing payment gateways in Bagisto (examples: Custom Stripe Payment, PayPal Smart Button). It references integrating Stripe and PayPal, using SDKs for API calls, and implementing money-moving operations such as createOrder, captureOrder, getOrder, and refundOrder. These are specific, purpose-built payment integration capabilities (not generic tooling), so the agent could be given direct financial execution authority via the described integrations.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 26, 2026, 11:54 AM